Method: HeimdallTools::NiktoMapper#to_hdf

Defined in:
lib/heimdall_tools/nikto_mapper.rb

#to_hdfObject



108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
# File 'lib/heimdall_tools/nikto_mapper.rb', line 108

def to_hdf
  controls = []
  @project['vulnerabilities'].each do |vulnerability|
    printf("\rProcessing: %s", $spinner.next)

    item = {}
    item['tags']               = {}
    item['descriptions']       = []
    item['refs']               = NA_ARRAY
    item['source_location']    = NA_HASH
    item['descriptions']       = NA_ARRAY

    item['title']              = vulnerability['msg'].to_s
    item['id']                 = vulnerability['id'].to_s

    # Nikto results JSON does not description fields
    # Duplicating vulnerability msg field
    item['desc']               = vulnerability['msg'].to_s

    # Nitko does not provide finding severity; hard-coding severity to medium
    item['impact']             = impact('medium')
    item['code']               = NA_STRING
    item['results']            = finding(vulnerability)
    item['tags']['nist']       = nist_tag(vulnerability['id'].to_s)
    item['tags']['ösvdb']      = vulnerability['OSVDB']

    controls << item
  end

  controls = collapse_duplicates(controls)
  scaninfo = extract_scaninfo(@project)
  results = HeimdallDataFormat.new(profile_name: scaninfo['policy'],
                                   version: scaninfo['version'],
                                   title: "Nikto Target: #{scaninfo['projectName']}",
                                   summary: "Banner: #{scaninfo['summary']}",
                                   controls: controls,
                                   target_id: scaninfo['projectName'])
  results.to_hdf
end